Skip to content
Back to Blog
low severity April 10, 2025 · 4 min read

VetCT Data Breach Notice (Oregon Attorney General)

If you received a notice from VetCT, here’s what the filing says was exposed, and what to do about it.

VetCT notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 10, 2025.

VetCT Data Breach Notice (Oregon Attorney General)

The filing from VetCT, reported to the Oregon Department of Justice on April 10, 2025, states that personal information belonging to 52 people was exposed. If you received a letter from VetCT, your records were part of this incident. The organisation is required to notify affected individuals directly, usually by post. Absence of a letter usually means you were not included, but anyone who has moved since the incident should contact VetCT directly to confirm their status.

Personal Information That Cannot Be Replaced

The record lists personal information as the category exposed. Because no permanent government or biographic identifiers such as Social Security numbers were included, this breach carries a narrower set of long-term risks than many others. No passwords were exposed. This is genuinely good news: there is no credential risk here, and you do not need to change any passwords because of this incident.

Still, the exposed personal information creates persistent risks of identity theft, fraud, and targeted phishing. These risks do not decay over time the way a stolen credit card number does. Once personal details leave an organisation’s control, they can be combined with information from other sources to build convincing profiles for impersonation or social engineering attacks.

What the 52-Person Filing Actually Means for You

With only 52 Oregon residents named in the filing, this is a small incident by industry standards. The limited scope does not reduce the impact on those affected. When personal information leaves a veterinary imaging or diagnostic provider like VetCT, it can include details that feel deeply private: pet medical histories tied to owner contact information, billing records, or communication logs that reveal household circumstances.

Attackers do not need your Social Security number to cause harm. They can use personal information to craft phishing emails that reference your pet’s name, a recent procedure, or a specific invoice. These messages appear far more legitimate and are more likely to succeed. The same details can support fraudulent customer service calls or attempts to redirect communications.

The filing does not disclose the root cause, whether the data was merely accessed or exfiltrated, or the exact subtypes of personal information involved. This uncertainty is common in initial notifications but leaves affected individuals without a complete picture of what precisely left the organisation’s systems.

The Gap Between Incident and Notification

The record provides only the filing date of April 10, 2025. It does not state when the incident occurred. Without an incident date, it is impossible to measure how long the exposure may have lasted or how quickly VetCT responded. The letter you may have received is currently the only practical way to determine whether your information was involved.

Why This Exposure Matters Even Without SSNs

Personal information from a specialised provider like VetCT often contains context that makes it more valuable to fraudsters than isolated contact details. An address tied to veterinary records can reveal household size, pet ownership patterns, or even financial priorities visible through service choices. This contextual data helps attackers build convincing pretexts for further information gathering.

Targeted phishing and impersonation attempts become more effective when the attacker can demonstrate knowledge that only someone with access to your VetCT records would possess. These attacks do not rely on stealing your identity outright. They succeed by lowering your natural suspicion.

Because no passwords or login credentials were exposed, the core account you hold with VetCT itself remains secure. The risk lies in what attackers can do with the personal information outside of VetCT’s systems.

Practical Steps That Address This Specific Exposure

Monitor your mail and email closely over the coming weeks for any unexpected communications claiming to be from VetCT or related services. Verify every request for information by contacting the organisation using a phone number you already know to be legitimate, never one provided in an email or letter.

Be especially cautious of requests that reference your pets, recent procedures, or billing details. These are the exact pieces of personal information now potentially in circulation. Treat any such reference as a warning flag rather than proof of legitimacy.

Review recent explanations of benefits or billing statements from any connected insurance providers. While medical information was not explicitly listed beyond the general personal information category, veterinary records sometimes intersect with rider policies or flexible spending accounts that could create secondary exposure points.

Consider placing a fraud alert with the major credit bureaus even though no Social Security numbers were exposed. A fraud alert adds a layer of friction that can stop attempts to open accounts using personal details harvested from multiple breaches.

Contact VetCT directly if you have changed addresses since receiving services from them. Confirm whether your records were part of the group that triggered notification. Their obligation is to reach you at the address they have on file; it is your responsibility to make sure that address is still current.

This incident, though small, underscores that personal information retains value long after the initial breach. The 52 affected individuals cannot change what happened, but they can control how they respond to the increased risk of targeted social engineering that now exists.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed April 10, 2025
Last reviewed July 22, 2026
Affected 52
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email